
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27259 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager (AEM) that allows a low-privileged attacker to inject malicious scripts into vulnerable form fields. Affected versions include AEM 6.5.23 and earlier (on-premises) and AEM Cloud Service versions prior to 2026.02.0. The CVE was initially published on March 11, 2026, and has since been marked as Rejected by its CVE Numbering Authority, indicating it was issued in error. Despite the rejection, Adobe addressed a related stored XSS issue in AEM via security advisory APSB26-24. The associated CVSS v3.1 base score is 5.4 (Medium) (Adobe Advisory, Adobe DNG Advisory).
The vulnerability is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), with CWE-787 (Out-of-bounds Write) also associated in the Feedly data, though the primary issue is stored XSS. A low-privileged, network-accessible attacker can inject malicious JavaScript into form fields within AEM; when a victim navigates to a page containing the affected field, the script executes in their browser. Exploitation requires user interaction (a victim visiting the compromised page) and low privileges on the part of the attacker, with scope change indicating cross-context impact. Note that this CVE ID was formally rejected as issued in error by its CNA, so technical details should be interpreted with caution (Adobe Advisory).
If exploited, the stored XSS vulnerability could allow an attacker to steal session cookies, perform actions on behalf of authenticated victims, redirect users to malicious sites, or conduct phishing attacks within the context of the AEM application. The scope change in the CVSS scoring reflects that the injected script executes in the victim's browser context rather than the attacker's, potentially affecting confidentiality and integrity of user sessions. Availability is not directly impacted by this vulnerability (Adobe Advisory).
Adobe recommends upgrading Adobe Experience Manager on-premises to version 6.5.24 or later, and AEM Cloud Service to version 2026.02.0 or later, as addressed in security advisory APSB26-24. As additional hardening measures, organizations should implement Content Security Policy (CSP) headers to restrict unauthorized script execution, validate and sanitize all user inputs in form fields, and monitor for suspicious form submissions or unauthorized script injection attempts. Given that this CVE has been formally rejected, organizations should cross-reference with Adobe's official advisory APSB26-24 to confirm the specific fixes applicable to their environment (Adobe Advisory).
The CIS (Center for Internet Security) published an advisory noting multiple vulnerabilities in Adobe products that could allow for arbitrary code execution, referencing the April 2026 Adobe patch cycle that included AEM fixes. Beyond Machines and Fortress SRM also covered Adobe's April 2026 patch release in their threat and security update summaries. No significant independent researcher commentary or social media discussion specific to CVE-2026-27259 has been identified, likely due to its subsequent rejection status (CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."